First published: Thu Jul 10 2014(Updated: )
The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to bypass intended upload restrictions via a crafted parameter, aka Bug ID CSCup76297.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | ||
Cisco Unified Communications Manager | =10.0\(1\)_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3316 is considered a high severity vulnerability due to its potential to allow remote authenticated users to bypass upload restrictions.
To fix CVE-2014-3316, apply the relevant Cisco patch or upgrade to a fixed version of Cisco Unified Communications Manager.
CVE-2014-3316 affects Cisco Unified Communications Manager, particularly versions prior to 10.0(1) base.
Only remote authenticated users can exploit CVE-2014-3316 to bypass intended upload restrictions.
There is currently no documented workaround for CVE-2014-3316, so patching is the recommended action.